What's Happening?
Senator Ron Wyden has urged federal agencies to eliminate the use of outdated and insecure virtual private networks (VPNs) that are accessible via the public internet. In a letter addressed to the Office of Management and Budget, the Cybersecurity and Infrastructure
Security Agency, and the National Institute of Standards and Technology, Wyden emphasized the need for a shift towards modern, secure remote-access technologies. He highlighted the vulnerabilities associated with legacy VPNs, which have been exploited in several cyberattacks on federal agencies. Wyden advocates for the adoption of zero-trust architecture, which operates on a 'never-trust, always-verify' principle, to enhance cybersecurity across federal networks.
Why It's Important?
The call to transition from legacy VPNs to zero-trust architecture is significant in bolstering the cybersecurity framework of federal agencies. Legacy VPNs have been a weak point, allowing cyberattacks that compromise sensitive government data. By adopting zero-trust architecture, agencies can mitigate these risks, as this approach does not assume trust based on network location and requires continuous verification of user identity and access rights. This shift is crucial for protecting national security interests and maintaining the integrity of federal operations. The move could also set a precedent for private sector organizations to enhance their cybersecurity measures.
What's Next?
Senator Wyden has proposed that the Cybersecurity and Infrastructure Security Agency issue a directive giving agencies two years to phase out legacy VPNs. Additionally, he suggests that the National Institute of Standards and Technology develop implementation standards for zero-trust architectures. The Office of Management and Budget is expected to prioritize funding for this transition and collaborate with the Department of Defense to update procurement rules, ensuring compliance with zero-trust standards. These steps aim to create a more secure and resilient federal cybersecurity infrastructure.











